BOTA (Botnet Analysis) is a PoC system demonstrating possibilities of detecting devices infected by IoT malware. The detection pipeline leverages the concept of so-called weak indicators and heterogeneous meta-classifiers to maintain accuracy compared with the state-of-the-art systems while also providing explainable results that are easy to understand.
- docs.danieluhricek.cz/bota - BOTA documentation
- github.com/CESNET/ipfixprobe - flow exporter used by BOTA
- github.com/danieluhricek/bota-dataset - datasets
This research was funded by the Ministry of Interior of the Czech Republic, grant No. VJ02010024: Flow-Based Encrypted Traffic Analysis and also by the Grant Agency of the CTU in Prague, grant No. SGS20/210/OHK3/3T/18 funded by the MEYS of the Czech Republic.